A critical vulnerability disclosed August 1 in a widely used remote monitoring and management platform, the software many IT providers use to patch and access every client's systems, gave attackers unauthenticated administrative access. A hotfix shipped the next day, but attackers had already been exploiting it, prioritizing domain controllers on reachable networks. Days later, more than a quarter of vulnerable self hosted servers were still unpatched.
Most small firms do not run this software themselves, their outsourced IT provider does, which means a firm's security now depends on a system it has never seen, managed by a vendor whose patching habits it has likely never asked about.
Reasonable efforts under Rule 4-1.6 have to extend to the vendors holding the keys to a firm's systems, not just the firm's own devices.
ArisGate vets not just your systems but the vendors and tools that touch them. Schedule a free security audit today.